PT-2025-50069 · Vinod Dalvi+1 · Ivory Search+1
CVE-2025-63069
·
Published
2025-09-28
·
Updated
2025-12-09
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ivory Search versions prior to 5.5.13
Description
A missing authorization check in the
add-search-to-menu endpoint allows unauthenticated attackers to exploit incorrectly configured access control security levels. This occurs due to a missing capability check within a function, enabling unauthorized actions to be performed.Recommendations
Update to a version newer than 5.5.12.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivory Search
Add-Search-To-Menu